Human Security Help-desk vishing: the call that breaches a company
Groups like Scattered Spider call the IT help desk to reset MFA and breach the company. How the 2026 attacks work and how to verify identity.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Human Security Groups like Scattered Spider call the IT help desk to reset MFA and breach the company. How the 2026 attacks work and how to verify identity.
Careers and Certifications OSDA tests detection of attacker actions in a SIEM. Learn the SOC-200 ten-phase format, investigation queries, evidence and reporting workflow.
Careers and Certifications PNPT mirrors a professional pentest without CTF flags. Understand the five-day assessment, OSINT, Active Directory, report and live debrief.
Human Security A QR code slips past email filters and leads to a fake page straight from your phone. We explain how quishing works and how to defend against it.
Careers and Certifications CRTO focuses on Active Directory red-team operations. Build skills in C2, OPSEC, credential access, lateral movement and exam-ready methodology.
Cybersecurity History A secret NSA exploit went viral, and a few weeks later, WannaCry shut down hospitals and factories in 150 countries. The story of EternalBlue, the kill switch, and a lesson in patching.
Careers and Certifications HTB CPTS tests a complete infrastructure pentest and commercial report. Learn path requirements, the ten-day exam and an evidence workflow.
Human Security A SIM swap lets criminals take over your phone number — and with it your texts, codes and accounts. How it works, how to spot it and how to protect yourself.
Careers and Certifications BSCP is a four-hour practical web security exam. Learn the two-application structure, required Academy labs and a Burp Suite Professional workflow.
Vulnerabilities and CVEs Dozens of new vulnerabilities are published every day. We show how to tell the ones that actually affect you from the noise.
Human Security Criminals impersonate KSeF, e-government and gov.pl domains to target company finance teams. What this phishing looks like and how to secure it.
AI Security AI agents run code and tools on untrusted data. Build a sandbox with process, network, filesystem and secret isolation plus hard resource limits.
AI Security Browser agents read untrusted pages and act inside user sessions. Constrain cookies, origins, forms, downloads and the impact of prompt injection.
Cybersecurity History In 2003, the fastest worm in history doubled in size every few seconds, packed into a single package, and infected almost all vulnerable servers in 10 minutes - despite an existing patch.
AI Security A malicious API, MCP or CLI result can redirect an agent. Secure tool output with schemas, provenance, isolation and independent action policy.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.